vendor:
CommSy
by:
Jens Regel
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: CommSy
Affected Version From: 8.6.5
Affected Version To: 8.6.5
Patch Exists: NO
Related CWE: CVE-2019-11880
CPE: a:commsy:commsy
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
CommSy 8.6.5 – SQL injection
We have discovered a unauthenticated SQL injection vulnerability in CommSy <= 8.6.5 that makes it possible to read all database content. The vulnerability exists in the HTTP GET parameter 'cid'.
Mitigation:
According to the manufacturer, the version branch 8.6 is no longer supported and the vulnerability will not be fixed. Customers should update to the newest version 9.2.